Security at Screwge
Protecting the evidence behind every payment. Here is what we actually do to secure your data — and, just as importantly, what we have not built yet.
Data encryption
Data transmitted between users and Screwge is protected using encryption in transit. Information stored by Screwge is protected using the security controls provided by our managed infrastructure (Supabase and Vercel).
Tenant isolation
Customer information is logically isolated so that users can access only the organizations, projects, and records they are authorized to access. This is enforced with row-level security in the database, keyed to each organization — so that even a direct query cannot reach another organization's data. Nothing is shared across accounts.
Private document storage
Sensitive documents — site photos, compliance documents, identity and bank documents — are stored in private storage buckets, never publicly accessible. Access is granted through short-lived, signed links rather than open URLs.
Secrets stay server-side
Service credentials and AI provider keys are held only in our server environment and are never embedded in the app that runs in your browser. AI processing calls happen server-side through a secured function that validates each request.
Least-privilege access
Access to production data is limited to the people who need it to operate and support the service. We record security-relevant activity such as document and compliance actions to maintain an accountability trail.
Payments — Screwge does not move money
What we have not built yet
We would rather be honest than oversell. Today, Screwge is not SOC 2 or ISO 27001 certified, and we do not claim "bank-grade" or "military-grade" security. On our roadmap:
- Mandatory two-step verification (2FA) for owners and payment approvers, with step-up verification for sensitive actions.
- Expanded, centralized audit logging across sensitive actions and document access.
- Dedicated, segregated storage for identity and financial documents, and moving identity verification toward storing a result rather than a raw document.
- Formal backup and restore testing, and independent penetration testing.
- Independent certification (such as SOC 2 or ISO 27001) as customer demand justifies it.
We would rather implement these controls and then describe them than the other way around.
Responsible disclosure
If you believe you have discovered a security vulnerability in Screwge, please contact us at contactscrewge@gmail.com with the subject "Security". We investigate security reports and work to resolve verified vulnerabilities promptly. (A dedicated security@ address and a /.well-known/security.txt file are on our list as we set up domain email.)
Contact
Security questions: contactscrewge@gmail.com. See also our Privacy Policy, Terms, and Trust Center.